DeBabel is a project operated by an independent developer based in Switzerland. There is no company behind it at this time: references to "we", "us" or "DeBabel" refer to the developer in their personal capacity. The data controller is therefore the developer as a natural person, domiciled in Switzerland. The contact channel is privacy@debabel.org: we answer every request concerning your data and we disclose the controller's full identifying details to anyone entitled to them, including supervisory authorities and anyone who needs to exercise or enforce a right.
Processing is subject to the Swiss Federal Act on Data Protection (FADP) and, for users in the EU/EEA and the UK, to the GDPR to the extent it applies. The representative in the European Union under Art. 27 GDPR is in the process of being designated: their contact details will be shown here as soon as they are available. Until then, and in any case afterwards too, you can write directly to privacy@debabel.org on any matter relating to the processing of your data.
Who decides what. DeBabel is activated in a Discord server by an administrator of that server, who chooses whether to install it, in which channels and into which languages. Those choices determine which messages are translated and who can see them: in respect of them the administrator acts as data controller for their own server, and the Terms of Service require them to inform members and to make sure they have a legal basis for doing so (this page can be linked for that purpose). We are the controller for the technical operation of the service: translation, message mirrors, the retention described on this page, security and billing. Where the two spheres overlap we consider ourselves joint controllers under Art. 26 GDPR; in any case you can exercise your rights (Section 7) directly with us, without going through the server administrator. Discord Inc. and the providers listed in Section 5 process data under their own respective policies.
01What DeBabel does, briefly
DeBabel listens to messages posted in Discord channels where it has been installed by a server administrator, translates them into the languages configured for that server, and posts the translations as "mirror" messages in the corresponding channels. The same applies to images and GIFs: DeBabel recognizes the text in them, translates it, and reposts the image with the translated text. It also propagates edits, deletes, reactions and replies between mirrors, so that the original message and its translations stay in sync.
To do this, DeBabel needs to read the content of messages and of the images attached to them, link mirrors back to their original author, and remember each user's language preference for each server.
02What data we process
We process the following categories of data, all tied to your Discord user ID and the specific server (guild) where the activity happens:
- The content of messages you post in channels where DeBabel is active. Read in real time and sent to the translation provider (see Section 5) to produce the translated copy. We do not keep the text: we store only a "mirror" record with technical references (identifiers of the original message and of the translated copies, channel, language, author, date, and a fingerprint (hash) of the text used to detect whether the message has changed), so that edits and deletes can be propagated to the translated copies. When the content needs to be read again, we read it from Discord.
- Your language preference for each server. When you choose a language via
/debabel set-my-langor accept the welcome direct message, we store that choice so DeBabel knows which language channel to mirror your messages into. - Translation feedback you provide. If you report a translation ("Report translation" on the message), we keep the original text and the translation of the reported message, with the reason you give: the command tells you so, and you can choose to submit anonymously. The reported message may belong to another user: in that case its text is kept on the basis of our legitimate interest in service quality (Section 3), and the author can ask for its removal (Section 7). This helps us verify and correct translations. Corrections approved by the administrator remain as the server's translation rules (original text, corrected translation), with no link to who reported; they are deleted at the administrator's request, upon full removal of the server's data, and in any case within 365 days of uninstallation.
- The images and GIFs you post in channels where DeBabel is active. DeBabel downloads the image, recognizes the text in it through optical character recognition (OCR), translates that text, and reposts a version of the image with the translated text in the language channels. The image is processed in memory for translation; the recognized text is sent to the providers listed in Section 5, exactly like message text. For a subset of the processed images (those where the translation ran into difficulties, plus a small daily sample of the others; working material has fixed caps independent of traffic and excess copies are removed; the overall archive space is itself limited and, as it approaches the limit, redundant material is removed first), a copy of the original and of the recognized text may be retained, unlinked from your user ID, to check and improve the quality of image translation (legitimate interest, Section 3); most images are not retained at all: these copies are not published or shared, are accessible only to the developer, and may contain whatever information is visible in the image. Alongside the copy we keep a pseudonymized reference to the source message, used only to remove it on request. Images are not included in backups: in case of failure they are lost, and only the index remains. The server administrator can exclude their server from this retention by writing to privacy@debabel.org: from then on we keep none, and we remove the copies already kept that can be traced to that server. You can ask for a single image to be removed by giving the message link (Section 7). For servers where protected-term learning is enabled, we also retain the individual words recognized in the image, their position, and a fingerprint (hash) of the source image, with no link to your user ID whatsoever: these serve to identify fixed interface labels (for example, text from a video game) that should not be translated. These observations are tied to the server, not to you, and are deleted after 6 months.
- The polls you post in channels where DeBabel is active and the votes you cast. DeBabel translates the poll question and options and reposts a version in the language channels; to report the results we store the question, the options, their translations and the votes (who voted for what) linked to your user ID. This data is deleted at most 6 months after the poll closes.
- The reactions you add to translated or original messages. We store the emoji, the message it applies to and your user ID, only to reproduce and remove the reaction on the translated copies. No text: reactions follow the message and are deleted with it, after 12 months at most.
- Operational and technical data. Quality alerts and diagnostic data are kept briefly to let the bot self-monitor and recover from errors, and are deleted within 7 days. Technical metrics of translation calls (provider used, timings, volumes, cost) are recorded per server, with no message content and no personal identifiers, serve internal accounting and service reliability, and are deleted after 24 months.
- Data related to credit purchases. If you purchase credits for a server, the payment is handled by Polar (see Section 5), which acts as the merchant of record: we do not receive or store your card data. From the processor we receive a limited set of order information (technical transaction identifiers, amount, currency, and for real-money purchases the billing name and email address) necessary to register the credits on the server, provide support, and meet our accounting and tax obligations. Records of real-money purchases are kept for 10 years, as required by applicable accounting regulations; any postal address, phone number and IP address transmitted are removed from our records within 30 days. For credit movements that do not correspond to a monetary purchase (gift credits, consumption, internal refunds) we also remove name, email and user identifier within the same period, keeping only the technical references needed for internal accounting.
- Server configuration. Each server administrator provides a short server description and a channel-to-language mapping. This is server configuration data, not personal data about you, but we mention it for completeness.
We do not process: your credit card or payment instrument data (handled exclusively by the processor, see Section 5), voice content, attachments other than text, images and GIFs (for example documents, archives, audio or video files, which are ignored), your IP address beyond what Discord and our infrastructure providers see at the network layer, or any data outside the Discord servers where you have chosen to interact with the bot.
A note on images. Because DeBabel reads the text contained in images in order to translate it, any personal information visible in a screenshot you post (names, addresses, contact details, other people's conversations) is recognized and sent to the translation providers just like any other text. By posting content in a translated channel you represent that you have the right to share it, even where it contains information about other people: responsibility for that choice lies with the person posting. Weigh what you post in translated channels the same way you would weigh it for a text message.
Special categories of data. DeBabel is not designed to process special categories of personal data (Art. 9 GDPR: health, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic or biometric data), and the Terms of Service prohibit posting them in translated channels. If they do appear in a message or an image, they are processed only for the time technically needed to translate, follow the deletion rules in Section 4, and are neither used for any other purpose nor extracted in structured form. An administrator can switch image translation off entirely for their server with /debabel-server config image-translation action:disable, or leave the channels where such content circulates out of translation.
03Why we process it (legal basis)
For users in the EU, UK and other jurisdictions that require a legal basis under data protection law, the basis is one of the following:
- Performance of a contract (Art. 6(1)(b) GDPR). This covers the relationship with whoever installs and configures the bot on a server and with whoever purchases credits: there a contract with us exists, and processing the data needed to perform it is what makes the service possible.
- Legitimate interest (Art. 6(1)(f) GDPR). This is the basis on which we process message content, language preference and feedback of server members, who have no contract with us: the interest is delivering the translation the server has asked for and keeping originals and translated copies in sync. We have assessed that this interest does not override your rights, given that the messages are already visible in the channel where you post them, that we do not use them for other purposes, and that you can object at any time (Section 7). On the same basis we keep mirror records, short-lived operational data for service reliability, feedback for translation quality, and the image copies, unlinked from the author, used to check and improve image translation (Section 2).
- Legal obligation (Art. 6(1)(c) GDPR). The ten-year retention of purchase accounting records responds to a statutory obligation, and for that part we are not free to delete the data on request.
We do not use your messages, images or any other data to train artificial-intelligence models, ours or third parties', in line with Discord's Developer Policy; the providers listed in Section 5 are bound by the same prohibition. We make no automated decisions with legal or similarly significant effects on you and we do not profile you. If you don't want DeBabel to process your messages, the most direct option is to not post in channels where DeBabel is active. Server administrators can also configure which channels DeBabel mirrors.
04How long we keep your data
We keep each category of data only for as long as necessary for the purpose it was collected for, and we apply automatic cleanup routines to enforce these limits.
- Message mirrors are kept for as long as needed to support propagation of edits, deletes and reactions between language channels, and in any case for at most 12 months from the message's publication. After that they are removed.
- Translation feedback is kept for at most 6 months. The link to the person who reported is pseudonymized within 30 days. Correction rules approved by the administrator are deleted at the administrator's request, upon full removal of the server's data, and in any case within 365 days of uninstallation (Section 2).
- Polls (question, options, translations and votes) are deleted at most 6 months after the poll closes; reactions are deleted together with the message they apply to, after 12 months at most.
- Short-term operational data (quality alerts, diagnostics) is kept for a few days at most and then deleted. The bot's operational logs may contain the text of translated messages and are deleted within 7 days. Technical metrics with no content and no personal identifiers (Section 2) are deleted after 24 months.
- Your language preference for each server is kept until you change it, remove it, leave the server, or use the data-deletion command (see Section 7).
- Records of purchases in real money are kept for 10 years for tax purposes; data not needed for support (postal address, phone, IP) is removed within 30 days, and for non-monetary credit movements name, email and user identifier are also removed within the same period.
- Other service data: uncompleted purchase attempts are deleted within 90 days; payment incident records (disputes, refunds, failed payments) within 24 months of closure, except for the accounting part subject to the 10-year period; the log of privacy requests (access, deletion), kept in pseudonymized form to demonstrate how they were handled, is retained for 3 years.
- If the bot is removed from the server. When an administrator uninstalls DeBabel, that server's message mirrors are deleted within 30 days; server configuration and members' language preferences are kept for up to 365 days to allow the service to be restored on reinstallation, and are then deleted. The administrator can instead request immediate, complete deletion at the time of uninstallation (a full-removal option on the uninstall command): in that case all data for the server, including members' language preferences and feedback, is deleted right away, without waiting for the windows above. The operation is recorded in an audit log for compliance purposes.
- If the bot leaves automatically due to inactivity. If a server stays "paused" (no active translation) for 90 consecutive days, DeBabel leaves the server on its own, after sending a farewell message in the channel (a temporary message that does not replace this notice). The 90-day count resets to zero on any reactivation, even a single day of activity. For data-retention purposes this exit is treated the same as the manual uninstallation described in the point above (message mirrors deleted within 30 days, configuration and preferences kept for up to 365 days in case of reinstallation), with two differences: since it is not a request from the user, it does not trigger immediate, complete deletion (available only by choosing the dedicated option at the time of manual uninstallation); and the server's credit balance, not being subject to these windows, is kept indefinitely and becomes visible again if the server reinstalls the bot.
These windows describe the maximum retention absent a deletion request, and reflect what we currently consider proportionate; we may adjust them (more likely shortening than lengthening them) and any change will be reflected on this page. Your individual rights remain unaffected in any case: you can request deletion of your data at any time with /debabel privacy delete-my-data, regardless of what the server administrator has decided (see Section 7).
05Where your data goes (sub-processors and international transfers)
To deliver translations, DeBabel relies on a small number of third-party service providers, each with their own role.
DeBabel runs on a server operated by Hetzner Online GmbH in Germany. Translation requests are routed to LLM inference providers based on your geographic location and the type of request.
Text recognition in images (OCR) is handled by Mistral AI SAS for all users, regardless of jurisdiction: images posted in translated channels are transmitted to Mistral for text extraction. Mistral is an EU-based entity (see below). The text extracted this way then follows the same translation path as message text, described below. To verify the quality of translated images, the rendered image and its source may also be sent to language-model providers based in the United States, which keep them for at most 30 days solely for security and abuse prevention and do not use them to train their models; the transfer relies on the Data Privacy Framework certification and, subsidiarily, on the Standard Contractual Clauses.
Where messages are processed. By default, and regardless of where the author is located, each server's messages are processed by the providers listed below (based in the United States and in the EU), with the safeguards described under "International transfers". Text recognition in images (OCR) is always performed by Mistral AI SAS, a French company headquartered at 15 rue des Halles, 75001 Paris, France (SIRET 952 418 325). At the administrator's request and under a separate agreement with DeBabel, a server can be configured with the EU residency profile: in that case all messages and images of that server are processed exclusively by EU-based providers (Mistral AI and, secondarily, Infercom SCS, incorporated in Luxembourg with inference infrastructure in Germany), with no fallback to non-EU providers even on failure. No server currently uses this profile.
Providers of the default profile: DeBabel uses a set of US-based providers, in priority order: Cerebras Systems Inc., Groq Inc., Deep Infra Inc. (DeepInfra), and Nebius Group N.V. (US operations). These providers process message text, and text extracted from images, only for the duration of the inference request. Cerebras applies an immediate no-retention policy. Groq operates with Zero Data Retention active on our account: it does not retain inference request inputs/outputs. DeepInfra does not retain request content, except for a limited period for technical troubleshooting, as provided in its terms. Nebius and Mistral operate with zero-retention active on our account. None of these providers uses your data to train their models. For service continuity we may also use backup inference providers of the same category and under the same conditions: no training on your data, no retention beyond what is stated in this section, and transfers based on the Data Privacy Framework or the Standard Contractual Clauses.
Payments. Credit purchases are handled by Polar Software Inc. (United States) as merchant of record: Polar is the contractual counterparty to your purchase, collects the payment, calculates and remits applicable taxes, issues the invoice, and handles refunds and disputes. Polar collects and processes payment and billing data as an independent controller, under its own policy (polar.sh/legal/privacy); card processing is carried out through its collection providers. We do not see or store card data: we receive from Polar only the order data described in Section 2. Transfers to Polar from the EU/EEA, the UK and Switzerland take place on the basis of the Standard Contractual Clauses adopted by the European Commission.
Network traffic between users and our infrastructure is routed through Cloudflare, Inc. for DNS resolution, edge protection, and the secure tunnel that exposes the bot's management interface; Cloudflare also manages the DNS for debabel.org. Discord itself is the platform on which the bot operates and is, of course, the source and destination of all messages DeBabel reads and writes.
International transfers. Transfers to EU-based providers (Mistral AI, Infercom, Hetzner) stay within the EU/EEA and require no adequacy decision or transfer mechanism. Where data is transferred from the EU/EEA, the UK or Switzerland to the United States, which is the case for transfers to the global-tier providers (Cerebras, Groq, DeepInfra, Nebius), to Polar, and to Cloudflare, Inc., those transfers rely, depending on the recipient, on: certification to the Data Privacy Framework (EU-U.S. DPF, and the Swiss-U.S. DPF for transfers from Switzerland, recognized as adequate by the Federal Council), where the recipient is certified to it; or on the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by the adaptations recognized by the FDPIC for transfers from Switzerland. Hetzner hosts the server but does not access application data.
You can find current information about each of these providers' security and privacy practices on their respective websites.
Changes to providers. The list above is the one in force as of the date of this page. We may replace a provider, or add one of an equivalent nature (inference, text recognition, infrastructure, payments), where this serves the continuity, quality or sustainability of the service: in that case we update this page before the new provider goes live, and material changes are communicated as described in Section 10.
If you use DeBabel for an organisation. Where you are the controller of your members' data and you need a data processing agreement under Art. 28 GDPR, we make one available on request: write to privacy@debabel.org.
06Who can see your data
Within DeBabel:
- Other members of the Discord server where you post messages can see your translated messages in their respective language channels. This is the intended behavior of the bot: translations are delivered as Discord messages, not as private content. If you don't want a message to be translated and made visible to others, don't post it in a channel where DeBabel is active.
- Administrators of the Discord server where you interact with the bot can configure the bot, manage which channels are translated, and receive operational notifications about the bot's activity in their server. They do not have access to historical translation records of individual users through the bot itself; they see only what is posted on Discord.
- The DeBabel developer has technical access to the database, to the operational logs (which may contain message text for at most 7 days) and to the image copies kept for quality checks, for the purposes of operating, debugging and improving the bot, including investigating reported quality issues. This access is used solely for those purposes and is not shared.
We do not sell, rent, or share your data with any party for advertising, profiling, or any commercial purpose unrelated to running the bot. DeBabel does not contain advertising.
If we are ever legally required to disclose data (for example in response to a valid legal request from a competent authority) we will do so only to the extent strictly necessary and, where the law permits, we will inform you.
07Your rights and how to exercise them
Regardless of where you live, DeBabel offers the same set of practical rights to all users. Depending on your jurisdiction (EU/EEA, UK, Switzerland, California, Brazil, China, Japan, South Korea, Singapore, South Africa, the UAE, Saudi Arabia, Australia and others), you may have additional statutory rights: the rights listed below are designed to satisfy the common core of these laws.
You can:
- Access your data. Use
/debabel privacy export-my-datain any server where DeBabel is active. The bot will send you a JSON file with your stored data for that server via direct message. For a complete cross-server export, write to privacy@debabel.org. - Delete your data. Use
/debabel privacy delete-my-datain any server where DeBabel is active. After explicit confirmation, your language preference, feedback, reports and reactions for that server are permanently deleted, the authorship link to existing message mirrors and polls is removed (the mirrors themselves remain, without the author's identifier, to preserve edit/delete propagation for messages still active on Discord, and are removed within 12 months at most, Section 4). Image copies kept for quality checks are not linked to your ID and are not found by this command: to have one removed, write to privacy@debabel.org with the message link (or attach the image, if the message no longer exists). Not every image is retained: we check whether a copy exists, delete it if so, and in any case confirm the outcome to you. If the same image was also posted in another server, we remove its association with your message. - Get a summary of what we hold. Use
/debabel privacy infoto see, in your language, a short in-bot summary of categories, retention periods and rights. - Correct your data. Most data is either configuration you set yourself (your language preference, change it with
/debabel set-my-lang) or message content posted on Discord (edit it on Discord and the mirrors will update accordingly). For other corrections, write to privacy@debabel.org. - Object to or restrict processing. Stop using DeBabel's active channels and/or use
delete-my-data. For specific objection requests in cases provided by law, write to privacy@debabel.org. - Lodge a complaint with a supervisory authority. Users in the EU/EEA can lodge a complaint with their country's data protection authority. Swiss users can contact the Federal Data Protection and Information Commissioner (FDPIC). Users in other jurisdictions can refer to the local equivalent.
We will respond to written requests within the timelines required by applicable law (typically 30 days under the GDPR, 45 days under the CCPA).
A limit that is not up to us: accounting records of real-money purchases cannot be deleted on request for as long as the statutory retention obligation lasts (10 years). In that case we apply the minimization described in Section 4, stripping the record of data that is not necessary, but we cannot delete the record itself.
Aggregated and anonymous data. We may produce and use aggregated or anonymized statistics (for example: number of translations per language, average processing times) that cannot identify you; such data is not personal data and is not subject to this policy.
08Children
DeBabel is not directed at children. Discord's own Terms of Service require users to be at least 13 years old (or older in some jurisdictions). If you believe a child under the applicable age has provided data to DeBabel, write to privacy@debabel.org and we will remove it.
Purchases. Credit purchases are accessible to any member of the server. Refund requests or disputes over an unauthorized payment (including a purchase made by a minor using an adult's payment instrument) should be directed to Polar, which is the seller and contractual counterparty to the purchase (see Section 5): it is Polar that collects the payment and handles refunds and chargebacks. In these cases the order data we receive belongs to the payment holder, not to the minor; the payment holder can exercise their own rights over it like any other data subject (Section 7). What remains data about the minor is what is tied to their use of the bot on Discord (language preference, message mirrors, feedback) for which the above applies.
We cooperate either way. If whoever holds parental responsibility, or the payment holder, reports the situation to us, we delete all data referring to the minor without argument and minimize the data tied to the order to the strict indispensable: we do not ask for proof or raise formal obstacles. The only limit is the statutory one already noted in Section 4: the accounting record of a real-money purchase must be kept for the period required by tax law, but we strip it of identifying data that is not necessary. For any request of this kind: privacy@debabel.org.
09Security
Data is stored on dedicated infrastructure in Germany. The measures in place include: encryption of traffic in transit (TLS), system and database access restricted to the developer alone through encrypted and authenticated management channels, data minimization (this policy describes everything we retain), automated pseudonymization and deletion under the windows in Section 4, and regular system security updates. Database backups are encrypted before leaving the server and stored on Cloudflare R2 storage (see Section 5 for Cloudflare); deletions propagate to backups through their rotation, normally within 7 days and at most within 35. Image copies kept for quality checks are not part of the backups. We do not hold formal certifications (ISO 27001, SOC 2, etc.), as is normal for a project of this size; we will update this page if and when that changes.
In the event of a personal data breach we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Art. 33 GDPR. We inform affected individuals directly where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR), and in any case whenever applicable law requires it. We also notify Discord of any unauthorized access to data obtained through its APIs, as required by Discord's Developer Terms.
10Changes to this policy
We may update this policy as DeBabel evolves, for example if we add new features, change sub-processors, or formalize the legal entity behind the project. The "Last updated" date at the top of this page reflects the date of the most recent change. We consider material any change that introduces a new purpose, a new category of data, a longer retention period, a recipient outside the categories already listed in Section 5, a transfer to a country without the safeguards described here, or a reduction of your rights. Material changes will be communicated through the bot (welcome direct message and /debabel privacy info) before they take effect. Other changes (for example replacing a provider with an equivalent one, shortening a retention period, clarifications or corrections) take effect upon publication on this page and the update of the date at the top.
11Contact
For any privacy-related question or request, write to privacy@debabel.org. We reply within the timelines set out in Section 7.
For general questions about the bot, see debabel.org or the configuration commands inside Discord.